|
- <?php
- global $SESSION;
- function elgg_get_session() {
- return _elgg_services()->session;
- }
- function elgg_get_logged_in_user_entity() {
- return _elgg_services()->session->getLoggedInUser();
- }
- function elgg_get_logged_in_user_guid() {
- return _elgg_services()->session->getLoggedInUserGuid();
- }
- function elgg_is_logged_in() {
- return _elgg_services()->session->isLoggedIn();
- }
- function elgg_is_admin_logged_in() {
- return _elgg_services()->session->isAdminLoggedIn();
- }
- function elgg_is_admin_user($user_guid) {
- global $CONFIG;
- $user_guid = (int)$user_guid;
- $current_user = elgg_get_logged_in_user_entity();
- if ($current_user && $current_user->guid == $user_guid) {
- return $current_user->isAdmin();
- }
-
-
-
- $version = (int) datalist_get('version');
- if ($version < 2010040201) {
- $admin = elgg_get_metastring_id('admin');
- $yes = elgg_get_metastring_id('yes');
- $one = elgg_get_metastring_id('1');
- $query = "SELECT 1 FROM {$CONFIG->dbprefix}users_entity as e,
- {$CONFIG->dbprefix}metadata as md
- WHERE (
- md.name_id = '$admin'
- AND md.value_id IN ('$yes', '$one')
- AND e.guid = md.entity_guid
- AND e.guid = {$user_guid}
- AND e.banned = 'no'
- )";
- } else {
- $query = "SELECT 1 FROM {$CONFIG->dbprefix}users_entity as e
- WHERE (
- e.guid = {$user_guid}
- AND e.admin = 'yes'
- )";
- }
-
-
- $info = get_data($query);
- if (!((is_array($info) && count($info) < 1) || $info === false)) {
- return true;
- }
- return false;
- }
- function elgg_authenticate($username, $password) {
- $pam = new \ElggPAM('user');
- $credentials = array('username' => $username, 'password' => $password);
- $result = $pam->authenticate($credentials);
- if (!$result) {
- return $pam->getFailureMessage();
- }
- return true;
- }
- function pam_auth_userpass(array $credentials = array()) {
- if (!isset($credentials['username']) || !isset($credentials['password'])) {
- return false;
- }
- $user = get_user_by_username($credentials['username']);
- if (!$user) {
- throw new \LoginException(_elgg_services()->translator->translate('LoginException:UsernameFailure'));
- }
- if (check_rate_limit_exceeded($user->guid)) {
- throw new \LoginException(_elgg_services()->translator->translate('LoginException:AccountLocked'));
- }
- $password_svc = _elgg_services()->passwords;
- $password = $credentials['password'];
- $hash = $user->password_hash;
- if (!$hash) {
-
- $legacy_hash = $password_svc->generateLegacyHash($user, $password);
- if ($user->password !== $legacy_hash) {
- log_login_failure($user->guid);
- throw new \LoginException(_elgg_services()->translator->translate('LoginException:PasswordFailure'));
- }
-
- $password_svc->forcePasswordReset($user, $password);
- return true;
- }
- if (!$password_svc->verify($password, $hash)) {
- log_login_failure($user->guid);
- throw new \LoginException(_elgg_services()->translator->translate('LoginException:PasswordFailure'));
- }
- if ($password_svc->needsRehash($hash)) {
- $password_svc->forcePasswordReset($user, $password);
- }
- return true;
- }
- function log_login_failure($user_guid) {
- $user_guid = (int)$user_guid;
- $user = get_entity($user_guid);
- if (($user_guid) && ($user) && ($user instanceof \ElggUser)) {
- $fails = (int)$user->getPrivateSetting("login_failures");
- $fails++;
- $user->setPrivateSetting("login_failures", $fails);
- $user->setPrivateSetting("login_failure_$fails", time());
- return true;
- }
- return false;
- }
- function reset_login_failure_count($user_guid) {
- $user_guid = (int)$user_guid;
- $user = get_entity($user_guid);
- if (($user_guid) && ($user) && ($user instanceof \ElggUser)) {
- $fails = (int)$user->getPrivateSetting("login_failures");
- if ($fails) {
- for ($n = 1; $n <= $fails; $n++) {
- $user->removePrivateSetting("login_failure_$n");
- }
- $user->removePrivateSetting("login_failures");
- return true;
- }
-
- return true;
- }
- return false;
- }
- function check_rate_limit_exceeded($user_guid) {
-
- $limit = 5;
- $user_guid = (int)$user_guid;
- $user = get_entity($user_guid);
- if (($user_guid) && ($user) && ($user instanceof \ElggUser)) {
- $fails = (int)$user->getPrivateSetting("login_failures");
- if ($fails >= $limit) {
- $cnt = 0;
- $time = time();
- for ($n = $fails; $n > 0; $n--) {
- $f = $user->getPrivateSetting("login_failure_$n");
- if ($f > $time - (60 * 5)) {
- $cnt++;
- }
- if ($cnt == $limit) {
-
- return true;
- }
- }
- }
- }
- return false;
- }
- function elgg_set_cookie(\ElggCookie $cookie) {
- if (elgg_trigger_event('init:cookie', $cookie->name, $cookie)) {
- return setcookie($cookie->name, $cookie->value, $cookie->expire, $cookie->path,
- $cookie->domain, $cookie->secure, $cookie->httpOnly);
- }
- return false;
- }
- function login(\ElggUser $user, $persistent = false) {
- if ($user->isBanned()) {
- throw new \LoginException(elgg_echo('LoginException:BannedUser'));
- }
- $session = _elgg_services()->session;
-
- if (!elgg_trigger_before_event('login', 'user', $user)) {
- throw new \LoginException(elgg_echo('LoginException:Unknown'));
- }
-
-
- $session->setLoggedInUser($user);
-
- $message = "The 'login' event was deprecated. Register for 'login:before' or 'login:after'";
- $version = "1.9";
- if (!elgg_trigger_deprecated_event('login', 'user', $user, $message, $version)) {
- $session->removeLoggedInUser();
- throw new \LoginException(elgg_echo('LoginException:Unknown'));
- }
-
- if ($persistent) {
- _elgg_services()->persistentLogin->makeLoginPersistent($user);
- }
-
- $session->migrate();
- set_last_login($user->guid);
- reset_login_failure_count($user->guid);
- elgg_trigger_after_event('login', 'user', $user);
-
- if (is_memcache_available()) {
- $guid = $user->getGUID();
-
- register_shutdown_function("_elgg_invalidate_memcache_for_entity", $guid);
- }
- return true;
- }
- function logout() {
- $session = _elgg_services()->session;
- $user = $session->getLoggedInUser();
- if (!$user) {
- return false;
- }
- if (!elgg_trigger_before_event('logout', 'user', $user)) {
- return false;
- }
-
- $message = "The 'logout' event was deprecated. Register for 'logout:before' or 'logout:after'";
- $version = "1.9";
- if (!elgg_trigger_deprecated_event('logout', 'user', $user, $message, $version)) {
- return false;
- }
- _elgg_services()->persistentLogin->removePersistentLogin();
-
- $old_msg = $session->get('msg');
- $session->invalidate();
- $session->set('msg', $old_msg);
- elgg_trigger_after_event('logout', 'user', $user);
- return true;
- }
- function _elgg_session_boot() {
- elgg_register_action('login', '', 'public');
- elgg_register_action('logout');
- register_pam_handler('pam_auth_userpass');
- $session = _elgg_services()->session;
- $session->start();
-
- if ($session->has('guid')) {
- $user = _elgg_services()->entityTable->get($session->get('guid'), 'user');
- if (!$user) {
-
- $session->invalidate();
- forward('');
- }
- $session->setLoggedInUser($user);
- _elgg_services()->persistentLogin->replaceLegacyToken($user);
- } else {
- $user = _elgg_services()->persistentLogin->bootSession();
- if ($user) {
- $session->setLoggedInUser($user);
- }
- }
- if ($session->has('guid')) {
- set_last_action($session->get('guid'));
- }
-
- global $SESSION;
- $SESSION = new \Elgg\DeprecationWrapper($session, "\$SESSION is deprecated", 1.9);
-
- $user = $session->getLoggedInUser();
- if ($user && $user->isBanned()) {
- logout();
- return false;
- }
- return true;
- }
|